RH / Xerces
Cantor, Scott
cantor.2 at osu.edu
Tue Feb 7 20:58:00 EST 2017
I happened to go looking for the first time in a while and located a bugzilla entry for the last Xerces security advisory I did [1] and it's out of limbo: they've marked RH6 and RH7 as Won't Fix. That's...quite something.
Quite frankly, I don't know that I feel particularly obligated to cover for them on this; I'm more concerned just from my own perspective as a deployer I guess. I figured I'd share this publically in case somebody who's a customer decides it's worth asking them about it.
Our options on this seem rather limited in either the short or long run:
- ship our own 3.1 build into /opt and convince people to manipulate Apache's LD_LIBRARY_PATH (that's going to be a hard sell IMHO)
- same as 1 but forcibly hack that LD_LIBRARY_PATH into /etc/sysconfig/apache (which is not my file, so I don't much like the idea)
- try and put together a viable 3.2 release at Apache that would make it possible to ship a non-conflicting Xerces library on all the distros we support (I think it unlikely any of them will ever ship Xerces again, and I certainly hope they don't)
- ask my magic unicorn companion to wave his horn and convert all my code to libxml2
-- Scott
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1348845
More information about the dev
mailing list